CVE-2026-17600Sonatype · Nexus_repository_manager
Vulnerability data via NVD (ingested)
Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose account was already logged in at the time of one of these actions could continue using their existing session to interact with the repository as though the account were still active, until that session independently expired. Depending on the permissions previously held, this could allow continued unauthorized access to read, modify, or delete repository content after access was intended to be revoked.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-17600product:"Sonatype Nexus Repository Manager"http.html:"Nexus Repository Manager"More intel sources (5)
vuln:CVE-2026-17600vulnerabilities.cve_id: CVE-2026-17600CVE-2026-17600CVE-2026-17600"CVE-2026-17600" exploit -site:nvd.nist.gov